CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's CRUSH (Controlled Replication Under Scalable Hashing) mapping system, specifically in the handling of bucket types during the decoding process. If exploited, a malformed CRUSH map could lead to improper indexing of the OSD weight array, potentially causing system instability or crashes. Organizations utilizing Linux systems with CRUSH for data storage should prioritize addressing this issue to maintain system integrity and prevent potential disruptions.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: libceph: reject zero bucket types in crush_decode CRUSH bucket type 0 is reserved for devices. The mapper relies on that invariant and uses type 0 to identify leaf devices. If crush_decode() accepts a bucket with type 0, a malformed CRUSH map can make the mapper treat a negative bucket ID as a device and pass it to is_out(), which then indexes the OSD weight array with a negative value. Reject zero bucket types while decoding the CRUSH map so the invalid state never reaches the mapper.